A vulnerability was found in Vmware Spring Security up to 6.4.15/6.5.9/7.0.4. It has been classified as problematic. This vulnerability affects unknown code of the component One-Time Token Login. The manipulation leads to time-of-check time-of-use.

This vulnerability is traded as CVE-2026-22751. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.